57,566 vulnerabilities published in 2026
NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path
OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook
wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received a
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanis
OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies t
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability a
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj
A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was
@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution,
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/n
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,
SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptograph
Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFold
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conver
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active
A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leadin
A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondar
OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow
The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0
@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7
Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0
Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated si
SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints t
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_c
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an applica
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histo
Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positione
A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file r
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Wi
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certif
Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generate
Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malfor
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataA
eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably pr
A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the users
OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlie
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Log
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds,
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assi
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response
A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirr
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started